Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive Administrator's Guide - Kerio Software Archive

download.kerio.com
from download.kerio.com More from this publisher
30.01.2015 Views

Kerio VPN If another DNS server than the DNS module in Kerio Control is used in the local network, use this option. DNS domain extension is also assigned to VPN clients. Domain extension specifies local domain. If the VPN client’s extension matches a local domain of the networks it connects to, it can use hostnames within this network (e.g. server). Otherwise, full name of the host including domain is required (e.g. server.company.local). DNS extension can be also resolved automatically or set manually: • Automatic resolution can be used in case that the host belongs to the Active Directory domain and/or in case that firewall users are authenticated in this domain (see chapter 16.1). • DNS domain must be specified in case that it is a Windows NT domain or a network without a domain, or in case that another domain extension is desirable (e.g. when multiple Active Directory are mapped). Note: DNS servers assigned by the VPN server will be used as primary/secondary DNS server(s) on the client host. This implies that all DNS queries from the client host will be sent to these servers. However, in most cases this kind of “redirection” has no side effects. Upon closing of the VPN connection, the original DNS configuration will be recovered. WINS configuration for VPN clients The WINS service is used for resolution of hostnames to IP addresses within Microsoft Windows networks. Assigning of a WINS server address then allows VPN clients browse in LAN hosts (Network Neighborhood / My Network Places). Figure 23.5 VPN server settings — specification of WINS servers for VPN clients 312

23.1 VPN Server Configuration Kerio Control can detect WINS servers either automatically (using its host configuration) or use specified addresses of primary or/and secondary WINS server(s). Automatic configuration can be used if you are sure that WINS servers on the Kerio Control host are set correctly. Advanced Options Figure 23.6 VPN server settings — server port and routes for VPN clients Listen on port The port on which the VPN server listens for incoming connections (both TCP and UDP protocols are used). The port 4090 is set as default (under usual circumstances it is not necessary to switch to another port). Note: 1. If the VPN server is already running, all VPN clients will be automatically disconnected during the port change. 2. If it is not possible to run the VPN server at the specified port (the port is used by another service), the following error will be reported in the Error log (see chapter 22.8) upon clicking on the Apply button: (4103:10048) Socket error: Unable to bind socket for service to port 4090. (5002) Failed to start service "VPN" bound to address 192.168.1.1. 313

<strong>Kerio</strong> VPN<br />

If another DNS server than the DNS module in <strong>Kerio</strong> Control is used in the local<br />

network, use this option.<br />

DNS domain extension is also assigned to VPN clients. Domain extension specifies local<br />

domain. If the VPN client’s extension matches a local domain of the networks it connects<br />

to, it can use hostnames within this network (e.g. server). Otherwise, full name of the host<br />

including domain is required (e.g. server.company.local).<br />

DNS extension can be also resolved automatically or set manually:<br />

• Automatic resolution can be used in case that the host belongs to the Active Directory<br />

domain and/or in case that firewall users are authenticated in this domain (see<br />

chapter 16.1).<br />

• DNS domain must be specified in case that it is a Windows NT domain or a network<br />

without a domain, or in case that another domain extension is desirable (e.g. when<br />

multiple Active Directory are mapped).<br />

Note: DNS servers assigned by the VPN server will be used as primary/secondary DNS server(s)<br />

on the client host. This implies that all DNS queries from the client host will be sent to these<br />

servers. However, in most cases this kind of “redirection” has no side effects. Upon closing of<br />

the VPN connection, the original DNS configuration will be recovered.<br />

WINS configuration for VPN clients<br />

The WINS service is used for resolution of hostnames to IP addresses within Microsoft Windows<br />

networks. Assigning of a WINS server address then allows VPN clients browse in LAN hosts<br />

(Network Neighborhood / My Network Places).<br />

Figure 23.5<br />

VPN server settings — specification of WINS servers for VPN clients<br />

312

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!